Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Share this article

Significant Data Fiduciary under the DPDP Act: who qualifies and what changes (Section 10)

How the government designates a Significant Data Fiduciary, the extra Section 10 duties (India-based DPO, independent auditor, DPIAs) and how to prepare if you might qualify.

Most organisations under the DPDP Act are ordinary Data Fiduciaries. A smaller group carries a heavier set of duties: Significant Data Fiduciaries (SDFs). If you might be one, the extra obligations change your compliance plan materially, so it is worth knowing early.

Who becomes an SDF

The Central Government notifies a Data Fiduciary, or a class of them, as significant based on factors set out in Section 10: the volume and sensitivity of personal data processed, the risk to Data Principals, potential effects on the sovereignty and integrity of India, risks to electoral democracy, and security of the state. There is no single number, it is a risk-and-impact judgement the government makes.

What changes if you are one

What to do if you might qualify

If your data volume is large or you handle sensitive categories, plan as if you may be notified: the DPO and audit functions take time to stand up. The readiness assessment flags the SDF track when your answers suggest it, and a DPO or consultant can help you build the governance layer.

Frequently asked questions

Who decides if I am a Significant Data Fiduciary?
The Central Government notifies a Data Fiduciary or class as significant, based on Section 10 factors like data volume and sensitivity, risk to principals, and effects on state security and electoral democracy.
What extra duties does an SDF have?
An India-based Data Protection Officer, an independent Data Auditor, and periodic Data Protection Impact Assessments and audits, plus any further measures the government prescribes.
Is there a fixed data-volume threshold?
No single published number. It is a risk-and-impact assessment, so organisations with large volumes or sensitive data should prepare in case they are notified.

Guidance, not legal advice. dpdpactindia.in is an independent resource, not affiliated with the Government of India. Confirm specifics against the enacted Act and Rules.